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LISTING OF THE CLAIMS 

1 . (Currently Amended) A method for classifying electronic mail message transfer 
requests for policy enforcement comprising the steps of: 

identifying a source of an incoming electronic message; 
classifying said source; 

selecting a message transfer policy based upon the classification; and, 
applying a the selected message transfer policy associated with said classification 
for said source to said incoming electronic message . 

2. (Original) The method of claim 1 , wherein said identifying step comprises the 
step of identifying a network address for said source. 

3. (Original) The method of claim 1, wherein said classifying step comprises the 
step of classifying said source as one of a trusted source, a blocked source, and a suspect 
source. 

4. (Currently Amended) The method of claim 1, wherein said classifying step 
comprises the step of classifying said source as one of an authenticated source , a trusted 
source, a blocked source, and an anonymous source , and a suspect source . 

5. (Original) The method of claim 3, wherein said classifying step further 
comprises the step of classifying said source as a blocked source where said source 
appears in a realtime black hole list. 



2 



Application No. 10/789,574 
Filed: 2/27/2004 

Attorney Docket No. : LOT920040002US 1 (732 1 -044U) 

6. (Original) The method of claim 3, wherein said classifying step further 
comprises the step of classifying said source as a suspect source where said source 
appears in a realtime black hole list. 

7. (Original) The method of claim 4, wherein said classifying step further 
comprises the step of classifying said source as an authenticated source only where an 
authenticated connection has been established with said source. 

8. (Original) The method of claim 3, wherein said applying step comprises the 
step of limiting transfer of messages from a source classified as suspect. 

9. (Original) The method of claim 4, wherein said applying step comprises the 
step of limiting transfer of messages from a source classified as anonymous. 

10. (Currently Amended) A system for classifying electronic mail message transfer 
requests for policy enforcement comprising: 

a mail server; 

a set of mail transfer policies, each policy having an association with a 

corresponding source classification; 

at least one table of source identities having a particular classification; and, 
a classifier coupled to said mail server and said at least one table , the classifier 

identifying a source of an incoming electronic message in the mail server, classifying said 
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source with a classification in the at least one table, selecting one of the mail transfer 
policies based upon the classification, and applying the selected one of the mail transfer 
policies to said incoming electronic message . 

1 1 . (Original) The system of claim 10, wherein said at least one table comprises 
at least one table selected from the group consisting of a table of trusted sources, a table 
of authenticated sources, a table of suspect sources, a table of blocked sources, and a 
realtime black hole list. 

12. (Currently Amended) A machine readable storage having stored thereon a 
computer program for classifying electronic mail message transfer requests for policy 
enforcement, the computer program comprising a routine set of instructions which when 
executed by a machine cause the machine to perform the steps of: 

identifying a source of an incoming electronic message; 
classifying said source; 

selecting a message transfer policy based upon the classification; and, 
applying a the selected message transfer policy associated with said classification 
for said source to said incoming electronic message . 

13. (Original) The machine readable storage of claim 12, wherein said identifying 
step comprises the step of identifying a network address for said source. 
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14. (Original) The machine readable storage of claim 12, wherein said classifying 
step comprises the step of classifying said source as one of a trusted source, a blocked 
source, and a suspect source. 

15. (Currently Amended) The machine readable storage of claim 12, wherein said 
classifying step comprises the step of classifying said source as one of an authenticated 
source , a trusted source, a blocked source, and an anonymous source , and a suspect 

16. (Original) The machine readable storage of claim 14, wherein said classifying 
step further comprises the step of classifying said source as a blocked source where said 
source appears in a realtime black hole list. 

17. (Original) The machine readable storage of claim 14, wherein said classifying 
step further comprises the step of classifying said source as a suspect source where said 
source appears in a realtime black hole list. 

18. (Original) The machine readable storage of claim 15, wherein said classifying 
step further comprises the step of classifying said source as an authenticated source only 
where an authenticated connection has been established with said source. 

19. (Original) The machine readable storage of claim 14, wherein said applying 
step comprises the step of limiting transfer of messages from a source classified as 
suspect. 
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20. (Original) The machine readable storage of claim 15, wherein said applying 
step comprises the step of limiting transfer of messages from a source classified as 
anonymous. 
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